# Filebeat - non-deterministic error (pipestatus 141) when read from stdin

**URL:** <https://discuss.elastic.co/t/filebeat-non-deterministic-error-pipestatus-141-when-read-from-stdin/152968>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 18, 2018, 9:12am UTC](https://discuss.elastic.co/t/filebeat-non-deterministic-error-pipestatus-141-when-read-from-stdin/152968 "2018-10-18T09:12:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![krrz](https://avatars.discourse-cdn.com/v4/letter/k/ecb155/32.png) [@krrz](https://discuss.elastic.co/u/krrz)\
**Post date:** [October 18, 2018, 9:12am UTC](https://discuss.elastic.co/t/filebeat-non-deterministic-error-pipestatus-141-when-read-from-stdin/152968/1 "2018-10-18T09:12:19Z")

</div>

Hi,

when I start filebeat reading from stdin sometime its end with 141 pipe status.

```
# filebeat.1
zcat somefile.gz | filebeat -c filebeat.yml --once; rc=${PIPESTATUS[*]}; echo $rc
0 0
# filebeat
zcat somefile.gz | filebeat -c filebeat.yml --once; rc=${PIPESTATUS[*]}; echo $rc
141 0

```

filebeat version  
filebeat version 6.4.1 (amd64), libbeat 6.4.1 [37b5f2d2a20f2734b2373a454b4b4cbb2627e841 built 2018-09-13 21:25:47 +0000 UTC]

Logs

- filebeat.1

- filebeat

Thanks  
krrz

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 19, 2018, 12:07pm UTC](https://discuss.elastic.co/t/filebeat-non-deterministic-error-pipestatus-141-when-read-from-stdin/152968/2 "2018-10-19T12:07:30Z")

</div>

The `141` is the exit code of zcat. I think zcat returns the status code on SIGPIPE. Pipes can be tricky, they always need a reader and writer. If some process stops early or closes the pipe, then the other process will receive a SIGPIPE. The filebeat logs say `End of file reached`. Once filebeat reaches end of file on stdin, it expects no more input. This is when zcat receives SIGPIPE. Shutdown of the 2 processes and closing is pipe is racey, that's why sometimes you get the exit code and sometimes not.

---

<div class="post-metadata">

**Author:** ![krrz](https://avatars.discourse-cdn.com/v4/letter/k/ecb155/32.png) [@krrz](https://discuss.elastic.co/u/krrz)\
**Post date:** [October 19, 2018, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-non-deterministic-error-pipestatus-141-when-read-from-stdin/152968/3 "2018-10-19T13:09:44Z")

</div>

> The `141` is the exit code of zcat. I think zcat returns the status code on SIGPIPE. Pipes can be tricky, they always need a reader and writer. If some process stops early or closes the pipe, then the other process will receive a SIGPIPE.

True, true, true, true.

> The filebeat logs say `End of file reached` . Once filebeat reaches end of file on stdin, it expects no more input. This is when zcat receives SIGPIPE. Shutdown of the 2 processes and closing is pipe is racey, that's why sometimes you get the exit code and sometimes not.

Not true. `End of file reached` was log when

> PIPESTATUS

was

> 0 0

Sorry for my english. This is not my native language.

krrz

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 22, 2018, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-non-deterministic-error-pipestatus-141-when-read-from-stdin/152968/4 "2018-10-22T13:50:28Z")

</div>

I see, I mixed up the log files.

Looks like a bug. Searching on github I did find this issue: [https://github.com/elastic/beats/issues/3315](https://github.com/elastic/beats/issues/3315)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2018, 1:51pm UTC](https://discuss.elastic.co/t/filebeat-non-deterministic-error-pipestatus-141-when-read-from-stdin/152968/5 "2018-11-19T13:51:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
